[CLSA-2026:1788290829] Fix CVE(s): CVE-2024-6345, CVE-2025-47273
Type:
security
Severity:
Important
Release date:
2026-09-01 19:27:21 UTC
Description:
* SECURITY UPDATE: command injection in PackageIndex VCS downloads - debian/patches/CVE-2024-6345.patch: pass argv lists to subprocess.check_call() instead of interpolating the URL and revision into an os.system() shell string (CWE-78). - CVE-2024-6345 * SECURITY UPDATE: path traversal in the download filename - debian/patches/CVE-2025-47273.patch: sanitise the name derived from the URL so a percent-encoded absolute path cannot escape tmpdir (CWE-22). - CVE-2025-47273
Updated packages:
  • alt-python313-setuptools_69.0.2-3_all.deb
    sha:a98e389abc94287db6816f2aa4714d4f7d15c9b3
  • alt-python313-setuptools-wheel_69.0.2-3_all.deb
    sha:011bd9f295e39891b6ff4373190b133d9f224a3c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.